(In reply to comment #0)
> I have compiled samba 3.24 on SUSE 10.2 with default configure options.
> My setup looks like,
>
> SUSE PDC (SUSEDOM) running samba 3.2.4 which is trusting Windows 2003 domain
> (running in mixed mode) and a windows 2008 domain (running in windows 2000
> native mode). I could establish trust between these two domains.
>
> But when I try to login to the SUSE PDC with the windows 2008 domain
> credentials it fails with status logon failure. The wbinfo -u command does not
> display the users from 2008 whereas it displays all the users from the 2003
> domain and a login to SUSE PDC with windows 2003 domain credentials is
> successful.
>
> I tried to capture the network trace on windows 2008 domain controller when
> running "wbinfo -u" command, and what I found was SamrConnect2 RPC is failing
> with STATUS_ACCESS_DENIED. I suspect the error was because samba had opened the
> samr pipe with a anonymous login.
>
> Is there anything which I'm missing here, because samba 3.2 release notes say
> "Support for establishing interdomain trust relationships with Windows 2008"
This is true for domain members but was not correct for Samba as PDC. This just has been fixed very recently. You need to have Samba 3.3.9 at least (to be released on thursday, Oct. 14th) or Samba 3.4.2.

(In reply to comment #2)
> I was able to work around it by doing wbinfo --set-auth-user=user%password.
> Is there a way to fix it in the code?
No. Unfortunately not. Using this is the only option you have with your Samba version.
Side-note: For properly looking up names and SIDs in your w2k8 domain winbind needs to use LSA over ncacn_ip_tcp transport, something that is too complex to backport to the Samba 3.2 series. As said, Samba 3.3.9 and 3.4.2 will have this fixed.
Closing as "Fixed" in recent versions of Samba.